PT-2009-6212 · Gnu+2 · Gnu Automake+2

Ralf Wildenhues

+1

·

Publicado

2009-12-20

·

Atualizado

2024-06-15

·

CVE-2009-4029

CVSS v2.0

4.4

Média

VetorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU Automake versions 1.11.1, 1.10.3 GNU Automake release branches branch-1-4 through branch-1-9
Description The issue in GNU Automake allows local users to introduce a race condition, enabling them to modify package files, introduce Trojan horse programs, or conduct other attacks before the build is complete. This is due to insecure permissions (777) being assigned to directories in the build tree when producing a distribution tarball for a package that uses Automake.
Recommendations For GNU Automake versions 1.11.1 and 1.10.3, consider updating to a version that does not assign insecure permissions to directories in the build tree. For GNU Automake release branches branch-1-4 through branch-1-9, consider updating to a version that does not assign insecure permissions to directories in the build tree. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4029
OPENSUSE-SU-2024:10027-1
RHSA-2010:0321
RHSA-2010_0321
SUSE-SU-2013_1329-1

Produtos afetados

Gnu Automake
Red Hat
Suse